iio: frequency: admv1013: fix NULL pointer dereference on str
Summary
| CVE | CVE-2026-46282 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-08 17:16:45 UTC |
| Updated | 2026-06-08 17:16:45 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: iio: frequency: admv1013: fix NULL pointer dereference on str When device_property_read_string() fails, str is left uninitialized but the code falls through to strcmp(str, ...), dereferencing a garbage pointer. Replace manual read/strcmp with device_property_match_property_string() and consolidate the SE mode enums into a single sequential enum, mapping to hardware register values via a switch consistent with other bitfields in the driver. Several cleanup patches have been applied to this driver recently so this will need a manual backport. |
Risk And Classification
EPSS: 0.000180000 probability, percentile 0.047960000 (date 2026-06-12)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected da35a7b526d9b258a2cb8b7816f736a41b32176b 3a9d8ec2051c2d80158ed7bded5e158c42870037 git | Not specified |
| CNA | Linux | Linux | affected da35a7b526d9b258a2cb8b7816f736a41b32176b 5e9f1bad26df3d3afb3cbbfa408b6d6e809708ac git | Not specified |
| CNA | Linux | Linux | affected da35a7b526d9b258a2cb8b7816f736a41b32176b 2dc8d26690bf4e7226409563221c37bc095c94ff git | Not specified |
| CNA | Linux | Linux | affected da35a7b526d9b258a2cb8b7816f736a41b32176b aac0a51b16700b403a55b67ba495de021db78763 git | Not specified |
| CNA | Linux | Linux | affected 5.17 | Not specified |
| CNA | Linux | Linux | unaffected 5.17 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.86 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.27 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.0.4 7.0.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1-rc1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/2dc8d26690bf4e7226409563221c37bc095c94ff | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/5e9f1bad26df3d3afb3cbbfa408b6d6e809708ac | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/3a9d8ec2051c2d80158ed7bded5e158c42870037 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/aac0a51b16700b403a55b67ba495de021db78763 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.